A new threat intelligence report has painted a stark picture of the cyber risks facing the UK and Ireland, describing an environment in which ransomware gangs, nation-state spies and politically motivated hacktivists are increasingly working the same terrain, often against the same victims.
The “Cyber Threat Landscape: UK & Ireland” report, published by threat intelligence firm CYFIRMA, finds that financially motivated cybercriminals and state-aligned actors are frequently targeting the same sectors, finance, telecoms, technology, healthcare and government, and warns that cybercrime, espionage and geopolitical disruption are becoming harder to tell apart.
Russia, China, North Korea and Iran all in the mix
According to the report, Russia remains the most immediate geopolitical cyber threat to the region, with Russian-linked groups focused on critical infrastructure, undersea cables and disinformation tied to the ongoing war in Ukraine. China is flagged as the more significant long-term concern, with state-linked groups pursuing intellectual property theft and “living off the land” techniques designed to maintain quiet, persistent access inside critical networks.
The report also names several state-sponsored groups actively targeting the UK, including Russia’s APT28 (Fancy Bear) and APT29 (Cozy Bear), and China-linked APT15 and GALLIUM. It highlights a recent APT28 campaign that hijacks vulnerable home and small-office routers to redirect DNS traffic, quietly harvesting credentials and login tokens from unsuspecting users. North Korea’s Lazarus Group is also named in connection with fake job-offer lures targeting European defence and drone manufacturers, part of the long-running “Operation DreamJob” campaign.
Ransomware still dominates, with the UK bearing the brunt
Ransomware remains the most visible threat. CYFIRMA’s data shows Qilin as the most active gang targeting the region between January and May 2026, followed by DragonForce, The Gentlemen and Cl0p, with the UK absorbing the overwhelming majority of recorded victims. Ireland saw far fewer incidents, but the report notes that groups including The Gentlemen, Qilin and Interlock have all claimed Irish victims, and activity there peaked sharply in May 2026.
Professional services, manufacturing, real estate and IT emerged as the sectors hit hardest by ransomware, the report finds, with most groups now relying on double extortion, encrypting systems while also stealing data to threaten public leaks if a ransom isn’t paid.
Financially motivated crews get creative with social engineering
The report also details the tactics of financially motivated groups such as FIN6, which has been posing as job seekers on LinkedIn and Indeed to trick recruiters into opening fake résumé links laced with malware, and Scattered Spider, which continues to abuse identity and access management systems by impersonating employees to helpdesk staff in order to reset credentials or bypass multi-factor authentication.
Dark web trade in UK and Irish data continues unabated
Beyond ransomware, the report catalogues a steady stream of underground forum listings offering UK and Irish personal data for sale throughout 2026 — including an alleged 120-million-record database from a UK gambling platform, a combo list of more than 657,000 UK email-password pairs, and a dataset said to contain 734,000 UK student records. CYFIRMA says this reflects a growing emphasis among criminal groups on monetising stolen data and credentials rather than relying solely on encryption-based extortion.
Critical vulnerabilities add to the pressure
The report also flags a cluster of critical vulnerabilities disclosed during the period, including several rated 9.0 or above in the n8n workflow automation platform, Cisco’s Secure Firewall ASA and FTD software, Fortinet’s FortiOS and FortiProxy products, and VMware’s ESXi and Workstation platforms — several of which have already been linked to active exploitation.
What organisations should do
CYFIRMA’s recommendations for organisations in both countries include:
- Accelerating patching of internet-facing systems, VPNs and edge devices, which remain the most common entry point for both ransomware crews and state-backed actors.
- Enforcing phishing-resistant multi-factor authentication and tightening helpdesk identity-verification processes to blunt social engineering attacks like those used by Scattered Spider and FIN6.
- Testing ransomware and DDoS response plans, including backup recoverability, given the sustained pace of attacks on critical infrastructure and public services.
- Increasing scrutiny of third-party and vendor access, as supply chain compromise continues to be used to reach multiple organisations through a single trusted relationship.
The report’s overall message is one of convergence: as ransomware operators, spies and hacktivists increasingly pursue overlapping goals through similar tools and techniques, CYFIRMA argues that organisations can no longer treat these as separate risks to be managed in isolation.
The full research report can be found here: https://www.cyfirma.com/research/cyber-threat-landscape-uk-ireland/

